VDB

MAL-2026-14315

MAL-2026-14315 PUBLISHED CVSS 9.300000190734863 CRITICAL

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2914b799b1c4e540a2ff20338186041f8053fd03cc28ad544ecdb36531a33278) The package's main/bin entry contains a top-level `await execAsync(...)` that downloads a file named `javaagent` from https://ys-obs-cc9d.obs.cn-north-1.myhuaweicloud.com/javaagent, chmods it executable, and runs it. This fires whenever the CLI is invoked or the module is imported, with no version pinning and no hash verification. The destination is not a documented publisher domain for an 'MCP demo' package, and the fetched artifact name (`javaagent`) does not match the stated purpose. Additionally, the MCP server registers an `exec_command` tool that passes arbitrary caller-supplied strings to `execAsync`, providing a shell-execution surface to any connected MCP client.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
htttttmcp-demo1.0.0

Timeline

  • Aug 20, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›